—
GO-2026-4320
Arcane Has a Command Injection in Arcane Updater Lifecycle Labels That Enables RCE in github.com/getarcaneapp/arcane/backend
Quick fix
GO-2026-4320 — github.com/getarcaneapp/arcane/backend: upgrade to the fixed version with the command below.
go get github.com/getarcaneapp/arcane/backend@v0.0.0-20260114065515-5a9c2f92e11fDetails
Arcane Has a Command Injection in Arcane Updater Lifecycle Labels That Enables RCE in github.com/getarcaneapp/arcane/backend
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/getarcaneapp/arcane/backend
Introduced in:
0Fixed in: 0.0.0-20260114065515-5a9c2f92e11fFix
go get github.com/getarcaneapp/arcane/backend@v0.0.0-20260114065515-5a9c2f92e11fReferences
- https://github.com/getarcaneapp/arcane/security/advisories/GHSA-gjqq-6r35-w3r8[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-23520[ADVISORY]
- https://github.com/getarcaneapp/arcane/commit/5a9c2f92e11f86f8997da8c672844468f930b7e4[WEB]
- https://github.com/getarcaneapp/arcane/pull/1468[WEB]
- https://github.com/getarcaneapp/arcane/releases/tag/v1.13.0[WEB]